Lecture 2 Flashcards

(33 cards)

1
Q

What does Article 12 of the 1948 Universal Declaration of Human Rights state about privacy?

A

It prohibits arbitrary interference with privacy, family, home, or correspondence and protects against attacks on honour and reputation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How does the European Convention on Human Rights (Art. 8.1) define the right to privacy?

A

Everyone has the right to respect for their private and family life, home, and correspondence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the difference between the right to privacy and the right to data protection?

A

The right to privacy relates to private life, while the right to data protection applies to any processing of personal data, even outside the private sphere.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does Article 8 of the EU Charter of Fundamental Rights say about data protection?

A

It guarantees fair processing, rights to access and rectify personal data, and independent supervision.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Is the right to data protection recognized by the UN?

A

No, the UN does not recognize it as a human right, although it acknowledges its importance in a 2013 resolution.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Can the rights to privacy and data protection be limited?

A

Yes, to protect general interests or the rights of others, as long as the limitation is proportional.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the GDPR and when did it come into force?

A

The General Data Protection Regulation, effective since 25 May 2018, harmonizes data protection across the EU.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

To whom does the GDPR apply?

A

To all organizations processing data of individuals in the EU, including non-EU organizations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is considered personal data under GDPR?

A

Any data relating to an identifiable individual, including sensitive data like biometrics and sexual orientation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the difference between anonymized and pseudonymized data?

A

Anonymized data is not personal data; pseudonymized data can still identify someone indirectly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the role of a data controller versus a data processor?

A

The controller decides why and how data is processed; the processor acts on the controller’s behalf.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What constitutes valid consent under the GDPR?

A

Consent must be freely given, specific, informed, and unambiguous.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the 7 principles of data processing under the GDPR?

A

1) Lawfulness, fairness, transparency; 2) Purpose limitation; 3) Data minimization; 4) Accuracy; 5) Storage limitation; 6) Integrity and confidentiality; 7) Accountability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does the GDPR principle of data minimization mean?

A

Only the necessary data should be collected and processed for the stated purpose.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the principle of accountability under GDPR?

A

Controllers/processors must implement and demonstrate compliance measures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the role of national supervisory authorities under GDPR?

A

They enforce compliance, handle violations, and can impose fines or data deletion orders.

17
Q

What is the European Data Protection Board?

A

An EU body ensuring consistent GDPR application, composed of the European Data Protection Supervisor and national authorities.

18
Q

What are the 8 rights of data subjects under the GDPR?

A

1) To be informed; 2) Of access; 3) To rectification; 4) To erasure; 5) To restrict processing; 6) To data portability; 7) To object; 8) Against automated decision-making and profiling.

19
Q

What penalties can be imposed for GDPR violations?

A

Fines up to €20 million or 4% of global turnover, whichever is higher.

20
Q

What is the goal of the EU Data Strategy?

A

To create a single market for data with fair access and strong protections for privacy and competition.

21
Q

Which four regulations are central to the EU Data Strategy?

A

Digital Services Act (DSA), Digital Markets Act (DMA), Data Governance Act (DGA), and Data Act.

22
Q

What are the two components of the Digital Services Package?

A

The Digital Services Act (DSA) and the Digital Markets Act (DMA).

23
Q

What does the DSA regulate?

A

Intermediary digital service providers: content moderation, advertising transparency, and user rights.

24
Q

What are VLOPs and VLOSEs under the DSA?

A

Very Large Online Platforms/Search Engines with over 45 million EU users; subject to extra diligence rules.

25
Who are considered 'gatekeepers' under the DMA?
Large platforms like Amazon or Apple that act as gateways to consumers.
26
What obligations does the DMA place on gatekeepers?
Opt-in for data use, data portability, access rights, and prohibition of unfair practices.
27
What is the aim of the Data Governance Act?
To increase data availability through public sector re-use, intermediaries, and data altruism.
28
What is data altruism?
Voluntary sharing of data for the public good without compensation.
29
What type of organizations can register as data altruism entities?
Non-profits that are transparent and secure.
30
What is the focus of the Data Act?
Rules for data access and sharing in the context of the Internet of Things (IoT).
31
What protections does the Data Act offer to SMEs?
Protection against unfair contract terms imposed by large firms.
32
When will the Data Act become applicable?
It entered into force in January 2023 and will be applicable in September 2025.
33
What is Convention 108+?
The first binding international agreement on data protection, updated in 2018, open to non-European countries.